Skip to content
Send us a role
All live jobs

Engineering

DevSecOps Consultant

Architect CI/CD pipelines across Azure DevOps, GitLab and GitHub Actions, with AI-powered security scanning baked in at every stage.

Role details

Architect CI/CD pipelines across Azure DevOps, GitLab and GitHub Actions, with AI-powered security scanning baked in at every stage.

You'll own the DevSecOps platform end to end, designing pipeline standards and governance frameworks used by global development teams. That means integrating SAST, DAST and SCA tooling, managing container security across Kubernetes and Docker, and using AWS Bedrock and Azure OpenAI to automate vulnerability prioritisation and remediation workflows.

The thing that sets this apart from a standard DevSecOps role is the AI integration. You're not just running Checkmarx and calling it done. You'll be building LLM-assisted workflows that surface context-aware fix guidance directly inside developer pipelines, using GitHub Copilot to accelerate IaC authoring, and developing prompt engineering strategies to get real value from AI tooling across the SDLC.

You'll work across both Azure and AWS, applying zero-trust and least-privilege principles to cloud-native architectures. The stack includes Terraform, Ansible, Python, PowerShell, Helm, Azure Defender, AWS Security Hub and Secrets Manager. It's a hands-on role with genuine breadth, covering platform design, security automation, container hardening and cross-team enablement.

The team operates across distributed, cross-functional squads, so you'll spend time guiding developers on secure coding practices and AI tooling, contributing to threat modelling sessions, and producing documentation that actually gets used. If you've worked in financial services or a regulated environment with SOC 2 or ISO 27001 exposure, that'll serve you well here.

What You'll Do

  • Design and maintain CI/CD pipeline standards across Azure DevOps, GitLab CI and GitHub Actions, covering build, test, security and deployment stages.
  • Integrate SAST, DAST and SCA tools including Checkmarx, SonarQube, OWASP ZAP and MEND, with AI-driven vulnerability prioritisation to cut through alert noise.
  • Build and manage secure cloud-native infrastructure across Azure and AWS using Terraform and Ansible, including container security across Kubernetes and Docker.
  • Embed AWS Bedrock and Azure OpenAI into pipeline diagnostics and remediation workflows, and enable development squads on AI tooling best practices.

What You'll Need

  • 5+ years in a DevSecOps or DevOps engineering role with hands-on experience across Azure DevOps, GitLab CI/CD and GitHub Actions.
  • Proven SAST, DAST and SCA integration experience, plus solid IaC skills in Terraform and/or Ansible across Azure and AWS at scale.
  • Docker, Kubernetes and Helm, with scripting across Python and PowerShell for automation and tooling.
  • Familiarity with LLM integration, AWS Bedrock or Azure OpenAI in an engineering context, and a working understanding of OWASP, CVSS and shift-left security principles.

About the Company

They're a technology-led organisation running enterprise-grade engineering across Azure and AWS. The team operates with a security-first culture and is actively embedding AI into its DevSecOps practice. It's a distributed environment with genuine investment in modern tooling and cross-functional ways of working.

Apply

Please click the 'Apply' button. Don't worry if your CV isn't up to date - just send what you have.